An issue was discovered in LibVNCServer before 0.9.13. libvncclient/tls_openssl.c has a NULL pointer dereference.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14396
Reference (s):
- https://cert-portal.siemens.com/productcert/pdf/ssa-390195.pdf
- https://github.com/LibVNC/libvncserver/commit/33441d90a506d5f3ae9388f2752901227e430553
- https://github.com/LibVNC/libvncserver/compare/LibVNCServer-0.9.12 LibVNCServer-0.9.13
- UBUNTU:USN-4434-1
- URL: https://usn.ubuntu.com/4434-1/

